Vulnerabilities > Nortel > VPN Router 5000

DATE CVE VULNERABILITY TITLE RISK
2007-04-27 CVE-2007-2334 Remote Unauthorized Access vulnerability in Nortel Contivity and VPN Router 5000
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML files lacking certain verification tags, which allows remote attackers to access the administration interface and change the device configuration via certain requests.
network
low complexity
nortel
7.5
2007-04-27 CVE-2007-2333 Remote Unauthorized Access vulnerability in Nortel Contivity, VPN Router 5000 and VPN Router Portfolio
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote attackers to access the private network.
network
low complexity
nortel
critical
10.0
2007-04-27 CVE-2007-2332 Remote Unauthorized Access vulnerability in Nortel VPN Routers
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force attack on a hash from the LDAP store.
network
low complexity
nortel
critical
9.0
2005-05-27 CVE-2005-1802 Products Remote Denial of Service vulnerability in Nortel Networks
Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header.
network
low complexity
nortel
5.0